fix(deps): update dependency next to v15.5.18 [security] - autoclosed#508
fix(deps): update dependency next to v15.5.18 [security] - autoclosed#508renovate[bot] wants to merge 1 commit into
Conversation
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
c511f79 to
a947eff
Compare
a947eff to
7a88bc6
Compare
7a88bc6 to
5ff74f2
Compare
|
There as been no activity on this PR for the last 14 days. Please consider closing this PR. |
5ff74f2 to
2746ce0
Compare
2746ce0 to
6255b95
Compare
6255b95 to
9680811
Compare
9680811 to
6877268
Compare
6877268 to
0851db1
Compare
e5897d5 to
6990439
Compare
6990439 to
367ca3e
Compare
367ca3e to
7c941f1
Compare
7c941f1 to
5d2e200
Compare
5d2e200 to
35fb467
Compare
35fb467 to
c50f752
Compare
c50f752 to
0151f38
Compare
0151f38 to
c33b413
Compare
c33b413 to
6b60c5d
Compare
6b60c5d to
a84ed32
Compare
This PR contains the following updates:
15.5.16→15.5.18Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
CVE-2026-45109 / GHSA-26hh-7cqf-hhc6
More information
Details
Impact
It was found that the fix addressing CVE-2026-44575 did not apply to
middleware.tswith Turbopack. Refer to CVE-2026-44575 for further details.References
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
vercel/next.js (next)
v15.5.18Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.